Plugin4Shell: zero-click RCE hits Claude Code, Codex, Copilot and Gemini CLI plugins
Air Security researchers found Plugin4Shell, a zero-click RCE in the plugin marketplaces of Claude Code, OpenAI Codex, GitHub Copilot and Google Gemini CLI: agents run git checkout on a pinned SHA without verifying the code matches that commit. One PoC plugin spread to over 26,000 agents, while the SkillJacking campaign compromised 925 skills and 134,000 agents. Anthropic and OpenAI shipped fixes, Google deprecated Gemini CLI, and Copilot had no patch at disclosure.
- Flaw affects Claude Code, Codex, Copilot and Gemini CLI
- PoC plugin spread to over 26,000 agents before removal
- SkillJacking compromised 925 skills and 134,000 agents
- Anthropic and OpenAI patched; Copilot had no fix
Read next
Security